We take security seriously. Since our modular packages manage credentials, authentication, and database sessions, we maintain strict guidelines to protect developer ecosystems.
1. Reporting Vulnerabilities
If you discover any security vulnerability, please report it privately to security@forgekit.dev. Do not create public issues on Github until we investigate and release patches.
2. Token Signatures and Cryptography
Our active authentication modules utilize the native Web Cryptography API to generate secure, cryptographically random signatures without external Node.js dependencies.